Automated policy synthesis for system call sandboxing
Shankara Pailoor, Xinyu Wang, Hovav Shacham, Isil Dillig
摘要
System call whitelisting is a powerful sandboxing approach that can significantly reduce the capabilities of an attacker if an application is compromised. Given a policy that specifies which system calls can be invoked with what arguments, a sandboxing framework terminates any execution that violates the policy. While this mechanism greatly reduces the attack surface of a system, manually constructing these policies is time-consuming and error-prone. As a result, many applications -including those that take untrusted user input-opt not to use a system call sandbox.
Motivated by this problem, we propose a technique for automatically constructing system call whitelisting policies for a given application and policy DSL. Our method combines static code analysis and program synthesis to construct sound and precise policies that never erroneously terminate the application, while restricting the program's system call usage as much as possible. We have implemented our approach in a tool called Abhaya and experimentally evaluate it 674 Linux and OpenBSD applications by automatically synthesizing Seccomp-bpf and Pledge policies. Our experimental results indicate that Abhaya can efficiently generate useful and precise sandboxes for real-world applications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationNanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang 等CCS 2021 · 被引用 32 次
- Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionNikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas 等CCS 2021 · 被引用 27 次
- C2C: Fine-grained Configuration-driven System Call FilteringSeyedhamed Ghavamnia, Tapti Palit, Michalis PolychronakisCCS 2022 · 被引用 22 次
- Protect the System Call, Protect (Most of) the World with BASTIONChristopher Jelesnianski, Mohannad Ismail, Yeongjin Jang, Dan Williams 等ASPLOS 2023 · 被引用 15 次
- Gramine-TDX: A Lightweight OS Kernel for Confidential VMsDmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing 等CCS 2024 · 被引用 10 次
相关 Paper
- SysXCHG: Refining Privilege with Adaptive System Call FiltersAlexander J. Gaidis, Vaggelis Atlidakis, Vasileios P. KemerlisCCS 2023 · 被引用 9 次
- Building Dynamic System Call Sandbox with Partial Order AnalysisQuan Zhang, Chijin Zhou, Yiwen Xu, Zijing Yin 等OOPSLA 2023 · 被引用 5 次
- SysPart: Automated Temporal System Call Filtering for BinariesVidya Lakshmi Rajagopalan, Konstantinos Kleftogiorgos, Enes Göktas, Jun Xu 等CCS 2023 · 被引用 10 次
- Automated Synthesis of Effect Graph Policies for Microservice-Aware Stateful System Call SpecializationWilliam Blair, Frederico Araujo, Teryl Taylor, Jiyong JangS&P 2024 · 被引用 6 次
- KSG: Augmenting Kernel Fuzzing with System Call Specification GenerationHao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu 等USENIX ATC 2022 · 被引用 45 次
